Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Ransomware commonly deletes Windows shadow copies before encrypting data on the victim host. This hunt identifies powershell, wmic, vssadmin or vssvc executing with command line arguments containing delete and variations of shadow.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 2e3e9910-70c1-4822-804a-ee9919b0c419 |
| Tactics | Impact |
| Techniques | T1490 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
CommandLine contains "delete"CommandLine contains "shadow"CommandLine has_any "wmic"NewProcessName has_any "powershell.exe" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊